You basically need a router between the networks. I would recommend pfsense or opnsense or if you like cli vyOS. I run a pfsense that has my ISP router on the WAN port and a network interface for all VLANs and then I configured the firewall to allow specific traffic to specific devices in specific VLANs. For example my PC can reach the smart home controller website but no other device. And the samrthome devices only can reach the DNS in the ISP network (my kinda DMZ) and the router to reach the internet. And for every VLAN there are own rules where goes what communication.
You also can setup that on the managed switch which you would need for setting up VLANs.
It comes via FedEx in Germany. And at your door they hand it to you and don’t need a signature. At least that what‘s was with my first package.
Had to get some replacement as my FW keyboards had a short. So the replacement was a bit more nerve wrecking. The driver came 3 times always when I am not at home. After 3 time FedEx contacted me via phone to schedule a new date for delivery. But I guess there was an overlap as the driver didn’t come. I already had requested to pick it up at their hub via e-mail so I guess the driver got cancelled after my mail was processed. And then I went to their hub when the notification mail came I can pick it up.